<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Deny tcp src outside:  Error in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/deny-tcp-src-outside-error/m-p/3889513#M26918</link>
    <description>&lt;P&gt;Hi Guy's!&lt;/P&gt;&lt;P&gt;I have an issue I need some help with. In the log files we keep getting &lt;STRONG&gt;Deny tcp src outside:&amp;nbsp;&lt;/STRONG&gt;&amp;nbsp;when this happens we are unable to receive some emails.&amp;nbsp; I have attached a screen shot.&amp;nbsp; Any help would be appreciated!&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;PRE&gt;&lt;SPAN class="pEM_ErrMsg"&gt;%ASA-4-106023: Deny protocol src 
[&lt;EM&gt;interface_name&lt;/EM&gt;:&lt;EM&gt;source_address&lt;/EM&gt;/&lt;EM&gt;source_port&lt;/EM&gt;] [([&lt;EM&gt;idfw_user&lt;/EM&gt;|&lt;EM&gt;FQDN_string&lt;/EM&gt;], &lt;EM&gt;sg_info&lt;/EM&gt;)] 
dst &lt;EM&gt;interface_name&lt;/EM&gt;:&lt;EM&gt;dest_address&lt;/EM&gt;/&lt;EM&gt;dest_port&lt;/EM&gt; [([&lt;EM&gt;idfw_user&lt;/EM&gt;|&lt;EM&gt;FQDN_string&lt;/EM&gt;], &lt;EM&gt;sg_info&lt;/EM&gt;)] 
[type {&lt;EM&gt;string&lt;/EM&gt;}, code {&lt;EM&gt;code&lt;/EM&gt;}] by &lt;EM&gt;access_group acl_ID&lt;/EM&gt; [0x8ed66b60, 0xf8852875]&lt;/SPAN&gt;&lt;/PRE&gt;&lt;P class="pEE_ErrExp"&gt;A real IP packet was denied by the ACL. This message appears even if you do not have the &lt;STRONG&gt;log&lt;/STRONG&gt; option enabled for an ACL. The IP address is the real IP address instead of the values that display through NAT. Both user identity information and FQDN information is provided for the IP addresses if a matched one is found. The ASA logs either identity information (domain\user) or FQDN (if the username is not available). If the identity information or FQDN is available, the ASA logs this information for both the source and destination.&lt;/P&gt;</description>
    <pubDate>Fri, 12 Jul 2019 21:02:30 GMT</pubDate>
    <dc:creator>achavez@indianpueblo.com</dc:creator>
    <dc:date>2019-07-12T21:02:30Z</dc:date>
    <item>
      <title>Deny tcp src outside:  Error</title>
      <link>https://community.cisco.com/t5/network-security/deny-tcp-src-outside-error/m-p/3889513#M26918</link>
      <description>&lt;P&gt;Hi Guy's!&lt;/P&gt;&lt;P&gt;I have an issue I need some help with. In the log files we keep getting &lt;STRONG&gt;Deny tcp src outside:&amp;nbsp;&lt;/STRONG&gt;&amp;nbsp;when this happens we are unable to receive some emails.&amp;nbsp; I have attached a screen shot.&amp;nbsp; Any help would be appreciated!&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;PRE&gt;&lt;SPAN class="pEM_ErrMsg"&gt;%ASA-4-106023: Deny protocol src 
[&lt;EM&gt;interface_name&lt;/EM&gt;:&lt;EM&gt;source_address&lt;/EM&gt;/&lt;EM&gt;source_port&lt;/EM&gt;] [([&lt;EM&gt;idfw_user&lt;/EM&gt;|&lt;EM&gt;FQDN_string&lt;/EM&gt;], &lt;EM&gt;sg_info&lt;/EM&gt;)] 
dst &lt;EM&gt;interface_name&lt;/EM&gt;:&lt;EM&gt;dest_address&lt;/EM&gt;/&lt;EM&gt;dest_port&lt;/EM&gt; [([&lt;EM&gt;idfw_user&lt;/EM&gt;|&lt;EM&gt;FQDN_string&lt;/EM&gt;], &lt;EM&gt;sg_info&lt;/EM&gt;)] 
[type {&lt;EM&gt;string&lt;/EM&gt;}, code {&lt;EM&gt;code&lt;/EM&gt;}] by &lt;EM&gt;access_group acl_ID&lt;/EM&gt; [0x8ed66b60, 0xf8852875]&lt;/SPAN&gt;&lt;/PRE&gt;&lt;P class="pEE_ErrExp"&gt;A real IP packet was denied by the ACL. This message appears even if you do not have the &lt;STRONG&gt;log&lt;/STRONG&gt; option enabled for an ACL. The IP address is the real IP address instead of the values that display through NAT. Both user identity information and FQDN information is provided for the IP addresses if a matched one is found. The ASA logs either identity information (domain\user) or FQDN (if the username is not available). If the identity information or FQDN is available, the ASA logs this information for both the source and destination.&lt;/P&gt;</description>
      <pubDate>Fri, 12 Jul 2019 21:02:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/deny-tcp-src-outside-error/m-p/3889513#M26918</guid>
      <dc:creator>achavez@indianpueblo.com</dc:creator>
      <dc:date>2019-07-12T21:02:30Z</dc:date>
    </item>
    <item>
      <title>Re: Deny tcp src outside:  Error</title>
      <link>https://community.cisco.com/t5/network-security/deny-tcp-src-outside-error/m-p/3889785#M26921</link>
      <description>Hi&lt;BR /&gt;&lt;BR /&gt;Can you show your acl outside_in and if you're using objects please share them as well to be able to read it.&lt;BR /&gt;&lt;BR /&gt;Can you share also the nat config for this machine 10.10.0.6?</description>
      <pubDate>Sun, 14 Jul 2019 02:47:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/deny-tcp-src-outside-error/m-p/3889785#M26921</guid>
      <dc:creator>Francesco Molino</dc:creator>
      <dc:date>2019-07-14T02:47:17Z</dc:date>
    </item>
  </channel>
</rss>

